Data collection
What we collect, why, for how long and who else sees it, store by store, and what we do not do with any of it. The inventory below is the one the code is checked against; the retention figures are the ones the Privacy Policy states.
- 13Stores
- 8Hold personal data
- 5Subprocessors
- 0Models trained on your data
What we do not do
Stated once, in the same words the Privacy Policy carries. These are commitments, not a description of current practice that could drift.
- We do not use your account data, API requests, support tickets, reports, webhooks or seller listings to train, fine-tune or evaluate any machine-learning model, ours or anyone else’s.
- We do not sell, license or share your data with any AI provider for training. Where a model runs on this platform it reads public web pages and our own catalog, never data you sent us.
- We do not build behavioural profiles. Usage is counted per key for the allowance; nothing infers what you are building from what you request.
- The catalog you receive is ours to publish and yours to use under your plan. What you do with it, including training your own models on it where your plan permits, is not reported back to us.
What we collect
Every store, grouped by the surface that fills it, with its fields named as the code names them. ip_address in a store means the address is kept as sent, for the period shown, and then deleted with the row.
| Row | Data | Fields | Retention | Processors | Personal |
|---|---|---|---|---|---|
| The website and your account | |||||
| 01 | AccountTo run the account: sign-in, the plan, billing state and which emails you have asked for. | email, display_name, tier, notification_prefs, created_at | 30 days | Cloudflare, Stripe, Resend | Yes |
| 02 | API keysTo authenticate API calls. The key itself is shown once and stored only as a hash. | key_hash, name, tier, enabled, expires_at, last_used_at | While the account exists | Cloudflare | No |
| 03 | Website sessionsTo keep you signed in on the website and let you see and revoke your own sessions. | token_hash, ip_address, user_agent, device_label, last_active_at, expires_at | Until sign-out or expiry | Cloudflare | Yes |
| 04 | Sign-in historyTo show you your sign-in history and to notice a credential being attacked. | email, ip_address, user_agent, success, failure_reason, created_at | 30 days | Cloudflare | Yes |
| 05 | BillingTo bill the plan. Card numbers never reach us; Stripe holds them and we keep only its identifiers and the invoice record tax law requires. | stripe_customer_id, subscription_status, invoices | 7 years | Cloudflare, Stripe | Yes |
| 06 | Website analyticsTo see which pages are used, in aggregate. Loads only after you accept analytics in the cookie banner; denied by default. | page_views, aggregate_events | Never kept by us | Google Analytics | No |
| 07 | Website error reportsTo find a crash in the website before you report it. The website only; the API never reports to it. | stack_trace, page_url, browser, ip_address | 90 days | Sentry | Yes |
| The API | |||||
| 08 | API request logsRate limiting, abuse detection, the usage meter, debugging a request you report by its id. Query strings and bodies are not logged; response bodies are never logged. | request_id, method, path, status_code, duration_ms, api_key_id, user_id, tier, error_code, user_agent, ip_address, country_code, response_size | 90 days | Cloudflare | Yes |
| 09 | Usage countersThe monthly allowance and the daily cap. A count per key per day, nothing about the requests themselves. | api_key_id, date, request_count | While the account exists | Cloudflare | No |
| 10 | Support tickets and data reportsTo answer a ticket or act on a data-correction report. Attachments are private to the ticket and its owner. | subject, description, category, attachments, data_report_fields | While the account exists | Cloudflare | Yes |
| 11 | Webhook endpointsTo deliver catalog changes to an endpoint you registered, and to show you whether each delivery succeeded. | endpoint_url, events, signing_secret_hash, delivery_log | While the account exists | Cloudflare | No |
| 12 | Seller listingsTo list a shop and its offers, and to report the traffic those listings receive. Counts are per listing per day, never per visitor. | shop_name, website, contact_email, offers, click_counts | While the account exists | Cloudflare | Yes |
| This documentation | |||||
| 13 | Browser storageConveniences that live in your browser: the theme, the pages you opened, the key you pasted into the Try It console and its request history. None of it is sent to us. | theme, recently_viewed, playground_api_key, playground_history, cookie_choices | Never kept by us | Only us | No |
Retention periods are the ones the Privacy Policy states. Processors are the subprocessors that hold or transmit the store; every server-side store is hosted on Cloudflare.
Where a model runs
A model runs in 2 places on this platform. Each is listed with what it reads. Neither reads anything you sent us.
Industry news triage
Sorts harvested industry news into announcements and everything else.
- Reads
- Public RSS and Atom articles we fetched.
- Provider
- Workers AI
Specification extraction
Reads a manufacturer page and reports what it states for a field, for the accuracy benchmark.
- Reads
- Public manufacturer pages and our own catalog record.
- Provider
- OpenRouter
The reverse direction is documented on the AI & LLMs page: how to hand the API to your own model. That is your data flowing to your model, on your terms, and nothing about it flows back to us beyond the request counts every call produces.
Who else sees it
The subprocessors any store above names, with the stores that reach them. A provider not on this list never receives your data.
| Provider | Role | Region | Stores |
|---|---|---|---|
| Cloudflare | hosting, edge compute, database, object storage, security | US and global | Account, API keys, API request logs, Usage counters, Website sessions, Sign-in history, Billing, Support tickets and data reports, Webhook endpoints, Seller listings |
| Stripe | payments and subscription billing; card details never touch us | US and Ireland | Account, Billing |
| Google Analytics | opt-in analytics, loaded only after consent | US | Website analytics |
| Resend | login codes and account email | US | Account |
| Sentry | error reports from the website only; the API never reports to it | US | Website error reports |
The full subprocessor list, the transfer mechanism and the breach-notification commitment are on the data protections page.
Your data, your rights
Access, correction, deletion, portability and objection, under the GDPR and the Australian Privacy Principles. Most of it you can do yourself; the rest is one email to legal@buungroup.com.
- 01Export everything we hold on you from your profile: the account record, its sessions and sign-in history, as JSON.
- 02Delete the account from the same page. Personal data goes within the deletion window above; billing records stay for the period tax law requires, and nothing else survives.
- 03Revoke a session, rotate a key or disable one at any time. A revoked key stops working on the next request.
- 04Turn analytics off in the cookie banner at any time. It was off until you turned it on.
- 05Ask for anything else, or lodge a complaint, at legal@buungroup.com. Australian users may also contact the OAIC, and EEA users their local authority.
Privacy PolicyData Processing AgreementSubprocessorsCookie PolicyVulnerability DisclosureTrust CenterContent RemovalDMCA & CopyrightTerms of ServiceHow the platform protects data